Draft NOINDEX expansion 2026-08-10; overall scores unpublished
USB Malware Checklist
Removable media hygiene first: SecurityChecklist keeps this draft free-first and claim-safe. Unknown USB sticks are a classic surprise-code path. Treat found drives as hostile until proven otherwise. Optional paid cards use claim-ledger prices from 2026-08-09 (Bitdefender Antivirus Plus from $24.99/yr first year; Malwarebytes from $59.99/yr). Overall scores stay unpublished (unpublished). Who should not buy: anyone who has not confirmed OS updates and built-in protection, anyone stacking multiple always-on engines, or anyone who needs published lab detection rates before deciding.
- Guide · Free-first · Draft NOINDEX
Direct verdict
USB Malware Checklist: finish free controls first, then consider paid tools only for a leftover job you can name. Product scores stay unpublished (N/Pub) until signed test records exist.
Priority checklist
- Do not plug in found or unsolicited USB sticks
- Disable autorun/autoplay where practical
- Scan known sticks with built-in AV before opening files
- Prefer cloud transfer for untrusted files
- Use paid cleanup tools only if infection is confirmed
Ledger-verified starting prices show below when captured; otherwise cards stay confirm-live or pending. Overall scores stay unpublished (N/Pub). Never invent dollar amounts.
Start Antivirus Finder →Checklist
- 1Free
Refuse mystery media
Do not plug in USB sticks found in parking lots, conference swag of unknown origin, or unsolicited mail. The curiosity cost is high.
- Leave found drives alone
- Ask IT before using visitor media at work
- Prefer official file-sharing links
- 2Free
Harden how removable media opens
Turn off autoplay. On shared PCs, limit who can mount removable disks. Scan before opening documents with macros.
- Disable autoplay
- Scan before open
- Be wary of Office macros from USB paths
- 3Optional paid
Optional cleanup products
If a stick already executed something suspicious, use built-in scans first, then consider reputable cleanup tools. Avoid stacking always-on engines.
- Run Defender/built-in full scan
- Disconnect from sensitive accounts if compromise suspected
- Consider on-demand cleanup for leftovers
- 4Optional paid
Product analysis: Malwarebytes cleanup after a bad USB
After Defender full/offline scans, Malwarebytes Free or Windows Individual Standard from $59.99/yr (2026-08-09) fits residual cleanup. Bitdefender Antivirus Plus from $24.99/yr is for multi-device seats after the incident, not the first USB response. Scores stay unpublished.
- Contain and rotate critical passwords from a clean device
- Prefer official cleanup downloads only
- Keep one real-time engine
- 5Free
Scenario: conference swag stick of unknown origin
Do not plug it into a work or banking PC. Prefer official cloud links from the organizer. If you already plugged it in, disconnect, run Defender full scan, and treat account resets as higher priority than a new suite logo.
- Refuse unknown swag media on money PCs
- Scan known sticks you control before opening macros
- Skip dual always-on engines after a scare
- 6Free
Final verdict
Refuse mystery media and disable autoplay first. After a confirmed scare: Defender scans, then Malwarebytes cleanup if residual; Bitdefender only for leftover seats. Overall score stays unpublished (unpublished).
- Mystery USB refused
- Autoplay off
- Cleanup only after free scans
What this checklist does not cover
- Firmware-level USB attacks
- Users who will plug anything in
- Invented USB malware prevalence stats
Sources
- Removable media hygiene patterns, Autoplay, scan-before-open, refuse found media; no invented prevalence stats
- Bitdefender sources, data/claim-ledgers/bitdefender.json#bitdefender-starting-price; from $24.99/yr first year captured 2026-08-09
- Malwarebytes sources, data/claim-ledgers/malwarebytes.json; from $59.99/yr captured 2026-08-09
- Overall scores unpublished (unpublished), No invented lab scores, detection rates, or aggregate ratings on Batch39/40/41 drafts
- Vendor marketing pages, bitdefender.com / malwarebytes.com feature and pricing claims, not independent lab evidence
- Security Checklist methodology, How antivirus pages are structured before scores and detection rates publish, /methodology/
- Sources (T014), data/claim-ledgers/bitdefender.json + malwarebytes.json, starting prices verified 2026-08-09; lab scores unpublished
Final verdict
Use free controls first. Treat product scores as unpublished until signed test records exist. Affiliate payout never sets recommendations. Re-check volatile prices and plan names before purchase.
FAQ
Frequently asked questions
Update history
Draft NOINDEX expansion 2026-08-10; overall scores unpublished. Re-check free OS controls and any listed prices same-day before purchase. Overall scores stay unpublished until signed test records exist.
Internal links
Continue in this cluster
Hub, tools, and related pages from the inventory. No invented URLs.
Expert guides & insights
Related guides
Stay in the same problem space without jumping brands.
Want launch updates?
Get a note when new tools, comparisons, and product checks go live.
